RL Blog

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research
Mario Vuksan

Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming

The first Magic Quadrant™ for Software Supply Chain Security comes as, we feel, the demand for greater supply chain visibility explodes.

Read More about Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming
Gartner® Named RL a Software Supply Chain Security Visionary. Here’s What We See Coming

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBluesky

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

The inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security is outWe're A Visionary
Skip to main content
Contact UsSupportBlogCommunity
reversinglabsReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseProtect Virtual MachinesIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
Events
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu
AppSec & Supply Chain SecurityMarch 31, 2026

GenAI Security Project ramps up guidance

With AI ramping up risk, OWASP stepped up its project to help AppSec teams get up to speed — and take action.

John P. Mello Jr.
John P. Mello Jr., Freelance technology writer.John P. Mello Jr.
FacebookFacebookXX / TwitterLinkedInLinkedInblueskyBlueskyEmail Us
AI ramps up risk

New resources for providing practical guidance and tools for securing generative and agentic AI have been released by OWASP's GenAI Security Project.

The new resources expand the project's Q2 2026 Updated Landscape Guide by updating its vendor and tooling ecosystem documentation and by adding an agentic red-teaming taxonomy that provides a structured, lifecycle-wide framework for identifying, measuring, mitigating, and governing AI risk.

OWASP project co-chair and co-founder Scott Clinton said:

"With the pace of change around AI and agentic architectures and related risks, the landscape guide is updated two to three times a year to capture the latest risk and coverage areas mapped to solutions that are helping organizations to address these new risks."

Clinton added that the Q2 update has been revised based on solutions submitted to the project. The solutions are then mapped to the risks and mitigations. "This edition captures even more solutions that are focused on addressing the OWASP Top 10 Risks for Agentic Security we released in December last year."

Here are the key updates to OWASP's GenAI Security Project that matter.

[ See webinar: Develop Your Playbook for AI-Driven Software Risk ]

1. Project now connects risks to solutions

The landscape guide's purpose is simply to connect documented risks and mitigations to emerging or existing open-source or commercial solutions, Clinton explained.

"It documents what risks they cover, what mitigations they provide, and how they fit into the evolving secure SDLC for AI and agentic applications. The result is a guide that is community and practitioner driven, free of vendor bias, that goes beyond simply a list of solutions but mapping to specific capabilities across the SLDC."
—Scott Clinton

After the initial release of the OWASP Top 10 for LLMs, the project realized that while it was great to identify the risks of GenAI, it also raised many questions, Clinton said. Were there open-source or commercial solutions that could help with this?  What risks did they cover? What mitigations do they provide? How did these new risks impact the secure SLDC process and team roles, if any?

Since the guide was introduced, its listings have steadily grown. The first publication identified fewer than 30 solutions that address these risks. They now number nearly 200.

2. Red teaming outcomes in focus

Clinton expects the update to the documentation for the vendor and tooling ecosystem to help security practitioners and teams understand which solutions they may want to implement and what risks and mitigations their current tooling covers.

At the same time, he continued, they can gain an understanding of how to extend their existing SDLC processes to meet the requirements laid out to more securely support the development, deployment, and operation of GenAI and agentic applications and systems.

He added that the new red teaming landscape is a response to the community's need to better understand and educate one another about which solutions are the best fit for red teaming agentic and AI apps.

It also allows them to consider how to leverage AI and agentic capabilities to accelerate and improve red teaming outcomes.

"The working group looked across red, blue, and purple teaming roles and identified what key needs and capabilities were necessary. The red teaming taxonomy captures that. The landscape applies the taxonomy to a community-sourced list of solutions that meet some or all of the criteria, making it easier for red teams to improve their red teaming programs."
—Scott Clinton

3. AI ramps up need for education and resources

Since its founding in 2023, the project's ranks have swelled to 25,000 members. One driver behind membership growth, Clinton noted, is the rapid pace of technology, adoption, and change of GenAI and agentic deployments, which is driving a continuous need for education.

Another driver Clinton cited is the risk amplified by AI technology. Security practitioners on the front lines are facing AI and agentic attacks with increasing velocity, he explained, while CISOs and IT leaders are trying to manage their companies through that threat environment.

Yet another driver, he continued, is the desire of practitioners for help addressing their frontline needs. "They're looking to learn, looking to work with peers and want practical guidance free of vendor bias," he said.

"In short, we see continued growth because of the community. It is one of the leading places practitioners can learn, share, and collaborate to solve the immediate day-to-day problems they are facing with trusted, open, peer-reviewed guidance."
—Scott Clinton

AI redefines software risk

ReversingLabs’ Software Supply Chain Security Report 2026 focuses on how AI has fundamentally changed software development – and software supply chain risk – in 2025. With the rise of shadow AI in the form of AI-assisted coding and the popularity of public platforms such as Hugging Face, it became clear that enterprise governance is needed to manage the rising risks from AI.

One incident RL researchers discovered this past year showed how AI can heighten risk. The malicious campaign took place on Hugging Face after threat actors exploited the Python ML model file format known as Pickle to distribute malware. RL dubbed this new technique “nullifAI,” and it proved a fruitful one for threat actors, who used it again on PyPI to target users of Alibaba AI Labs – demonstrating that malware-embedded ML models have entered the threat landscape. 

Other threats linked to AI expanded in 2025. For example, prompt injection, which is a form of model corruption where an attacker attempts to manipulate an AI model, was listed as the No. 1 threat in OWASP’s Large Language Model (LLM) Top 10 list.

And, with model context protocol (MCP) servers booming in popularity, researchers discovered the first-ever instance of a malicious MCP server spotted in the wild — and distributed via npm. The malicious package, postmark-mcp, showed how the fast evolving MCP infrastructure can be exploited by attackers to extend their malicious reach.

Learn how RL's free Spectra Assure Community can help your development and AppSec teams get deep insights into your software supply chain via binary analysis.

Keep learning

  • Get up to speed on the Agentic Development Security tools landscape in this June 18 webinar with Forrester Sr. Analyst Janet Worthington.
  • Learn why binary analysis is a must-have control in the Gartner® CISO Playbook for Commercial Software Supply Chain Security.
  • Take a deep dive on the state of software security with RL's Software Supply Chain Security Report 2026. Plus: See the the webinar discussing the findings.

Explore RL's Spectra suite: Spectra Assure for software supply chain security, Spectra Detect for scalable file analysis, Spectra Analyze for malware analysis and threat hunting, and Spectra Intelligence for reputation data and intelligence.

Tags:AppSec & Supply Chain SecurityArtificial Intelligence (AI)/Machine Learning (ML)

More Blog Posts

Agentic AI architecture

Agentic AI risk isn't a model problem. It's an architecture problem.

Agentic AI is moving the perimeter from components to data — and most strategies aren't built for that.

Learn More about Agentic AI risk isn't a model problem. It's an architecture problem.
Agentic AI risk isn't a model problem. It's an architecture problem.
AI coding agents

The race to secure AI coding: 4 steps to rein agents in

Coding agents are privileged insiders — with keys to CI/CD pipelines even as they give rise to ‘slopsquatting.’ Here’s how to govern them.

Learn More about The race to secure AI coding: 4 steps to rein agents in
The race to secure AI coding: 4 steps to rein agents in
Shai-hulud worm DevOps

Update to npm blocks install scripts: What it means for AppSec

Disabling scripts by default closes the vector worms like Shai-Hulud rely on. Here's what the update fixes — and what it doesn't.

Learn More about Update to npm blocks install scripts: What it means for AppSec
Update to npm blocks install scripts: What it means for AppSec
MCP is the new API

MCP security tracks API's playbook — we know how that ends

The standard connecting AI agents to tools and data leaves security to others. Make it a do-over.

Learn More about MCP security tracks API's playbook — we know how that ends
MCP security tracks API's playbook — we know how that ends

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top